Public Key Credential Enrollment for Interoperable Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems rely on proprietary formats that create interoperability issues, requiring multiple credentials for different locations and resources, leading to inconvenience, increased administrative burden, and reduced flexibility, with potential security risks due to misplacement and vendor lock-in.
Innovation Solution
Implementing a Public Key Access Control (PKAAC) system that enables devices to generate PKI key pairs, with the public key serving as a credential, allowing for secure authentication and enrollment through a user's device, facilitating interoperability and user-friendly 'Bring Your Own Credential' (BYOC) access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If proprietary access control credentials are used for different buildings and locations, then access control security is provided, but interoperability is limited and multiple credentials are required
Solution Approach 1:
The patent implements a universal credential system where a single cryptographic credential can be used across multiple access control systems and locations. The credential is designed to be location-agnostic and system-agnostic, allowing users to access different buildings, floors, and resources with one credential rather than multiple proprietary credentials.
Solution Approach 2:
The patent introduces a credential as an intermediary between the user and access control systems. This credential acts as a universal mediator that can be recognized by multiple access control readers across different locations and systems, eliminating the need for multiple location-specific credentials.
2Reliability
If multiple access control credentials are required for different locations, then access security is maintained, but user convenience decreases and administrative burden increases
Solution Approach 1:
The credential is designed to provide universal access across multiple locations and systems while maintaining security. A single credential replaces multiple location-specific credentials, making the system easier to operate while preserving security through cryptographic verification at each access point.
Solution Approach 2:
The system enables users to self-enroll and self-manage their credentials without requiring administrative intervention for each new location or access point. Users can independently provision their own credentials that work across the entire system.
3Ease of manufacture
If proprietary credential formats are used, then access control functionality is provided, but vendor lock-in occurs and flexibility is reduced
Solution Approach 1:
The credential system is designed to be vendor-agnostic and system-agnostic, providing access control functionality across multiple platforms and locations without being tied to a specific vendor's proprietary format. This enables flexibility and prevents vendor lock-in while maintaining full access control functionality.
Solution Approach 2:
The system uses cryptographic parameters and formats that are standardized and vendor-neutral, allowing the same credential to work across different access control systems from different vendors. This changes the parameter space from proprietary formats to universal cryptographic formats.
4Ease of operation
If traditional access control systems are used, then access management is provided, but security risks increase due to credential misplacement and centralized vulnerability
Solution Approach 1:
The system segments the credential into cryptographic components distributed between the user device and the access control system. The private key remains on the user device while the public key is stored in the credential, eliminating the security risks associated with centralized credential storage and physical credential misplacement.
Solution Approach 2:
The system replaces physical credential mechanisms (cards, tokens, badges) with a cryptographic digital credential system. This substitution eliminates security risks associated with physical credential misplacement, loss, or theft, while maintaining ease of access management through digital verification.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Example aspects include techniques for enrollment of a public key for use as a physical or logical credential. These techniques may include receiving, at a first PKAAC access control reader with enrollment capabilities, a PKAAC authentication request from a PKAAC-enabled client application of a client device, and determining that the PKAAC authentication request corresponds to an identity that is unenrolled. In addition, the techniques may include collecting pre-enrollment information in response to the PKAAC authentication request corresponding to the identity that is unenrolled, and generating enrollment information based upon the pre-enrollment information, the enrollment information including authorization information indicating that the identity is authorized to access an access point. Further, the techniques may include providing, via a second PKAAC access control reader, access to the access point based on the authorization information.